{"generated":"2026-09-15T09:07:18.948Z","source":"Official RSS (CISA, vendor PSIRTs, security outlets)","count":40,"items":[{"title":"LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server","url":"https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html","source":"The Hacker News","published":"2026-09-15T06:52:16.000Z","why":"A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an&nbsp;advisory published on September 14. On such servers, many customers' si","classes":[]},{"title":"Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution","url":"https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html","source":"The Hacker News","published":"2026-09-15T06:11:11.000Z","why":"Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a ","classes":[]},{"title":"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE","url":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html","source":"The Hacker News","published":"2026-09-15T05:31:05.000Z","why":"A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tra","classes":[]},{"title":"Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries","url":"https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html","source":"The Hacker News","published":"2026-09-14T16:56:30.000Z","why":"A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. \"Red H","classes":[]},{"title":"⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits","url":"https://thehackernews.com/2026/09/weekly-recap-rogue-ai-agents-wechat.html","source":"The Hacker News","published":"2026-09-14T14:40:34.000Z","why":"AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is mo","classes":[]},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","url":"https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA advisories","published":"2026-09-14T12:00:00.000Z","why":"<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href=\"https:/","classes":[]},{"title":"AI Changed the Exposure Problem. Validation Needs to Change With It.","url":"https://thehackernews.com/2026/09/ai-changed-exposure-problem-validation.html","source":"The Hacker News","published":"2026-09-14T11:58:00.000Z","why":"There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have","classes":[]},{"title":"CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV","url":"https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html","source":"The Hacker News","published":"2026-09-12T15:54:45.000Z","why":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following rep","classes":[]},{"title":"OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers","url":"https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html","source":"The Hacker News","published":"2026-09-12T09:07:56.000Z","why":"The \"major malicious attack\" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senio","classes":[]},{"title":"GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure","url":"https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html","source":"The Hacker News","published":"2026-09-11T16:30:18.000Z","why":"GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score:","classes":[]},{"title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog","url":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog","source":"CISA advisories","published":"2026-09-11T12:00:00.000Z","why":"<p>CISA has added three new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href=\"htt","classes":[]},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","url":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA advisories","published":"2026-09-11T12:00:00.000Z","why":"<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href=\"https:/","classes":[]},{"title":"Your Critical Vulnerabilities Might Not Be Your Biggest Risk","url":"https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html","source":"The Hacker News","published":"2026-09-11T11:30:00.000Z","why":"Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vul","classes":[]},{"title":"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html","source":"The Hacker News","published":"2026-09-11T07:14:09.000Z","why":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in&nbsp;research","classes":[]},{"title":"PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws","url":"https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html","source":"The Hacker News","published":"2026-09-11T06:46:18.000Z","why":"PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development comp","classes":[]},{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","url":"https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA advisories","published":"2026-09-10T12:00:00.000Z","why":"<p>CISA has added two new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href=\"https","classes":[]},{"title":"Orthanc DICOM Server","url":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02","source":"CISA advisories","published":"2026-09-10T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-02.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an authenticate","classes":[]},{"title":"AVEVA Pipeline Integrity Monitor","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01","source":"CISA advisories","published":"2026-09-10T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-253-01.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker t","classes":[]},{"title":"ST Engineering iDirect iQ-Series Terminals (Update A)","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01","source":"CISA advisories","published":"2026-09-10T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker t","classes":[]},{"title":"NextGen Healthcare Mirth Connect","url":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01","source":"CISA advisories","published":"2026-09-10T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-01.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker ","classes":[]},{"title":"Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE","url":"https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html","source":"The Hacker News","published":"2026-09-10T11:45:05.000Z","why":"Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only \"under specific conditi","classes":[]},{"title":"PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances","url":"https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html","source":"The Hacker News","published":"2026-09-10T11:41:53.000Z","why":"A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. Accordi","classes":[]},{"title":"CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline","url":"https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html","source":"The Hacker News","published":"2026-09-10T10:36:46.000Z","why":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (","classes":[]},{"title":"Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example \"sk-1234\" Admin Key","url":"https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html","source":"The Hacker News","published":"2026-09-10T07:12:55.000Z","why":"Nearly one in ten of the internet-facing LiteLLM servers that&nbsp;Wiz Research&nbsp;scanned in February accepted&nbsp;sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company","classes":[]},{"title":"Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week","url":"https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html","source":"The Hacker News","published":"2026-09-09T16:34:05.000Z","why":"Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wil","classes":[]},{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","url":"https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA advisories","published":"2026-09-09T12:00:00.000Z","why":"<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <ul> <li><a hre","classes":[]},{"title":"DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval","url":"https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html","source":"The Hacker News","published":"2026-09-09T11:17:07.000Z","why":"A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-syste","classes":[]},{"title":"Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox","url":"https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html","source":"The Hacker News","published":"2026-09-09T09:11:03.000Z","why":"Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), ha","classes":[]},{"title":"Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed","url":"https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html","source":"The Hacker News","published":"2026-09-09T06:47:27.000Z","why":"The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score:","classes":[]},{"title":"SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution","url":"https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html","source":"The Hacker News","published":"2026-09-09T06:25:45.000Z","why":"SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the ap","classes":[]},{"title":"Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days","url":"https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html","source":"The Hacker News","published":"2026-09-09T04:41:29.000Z","why":"Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Wi","classes":[]},{"title":"N-able N-central Pre-Auth RCE Flaw Exploited in the Wild","url":"https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html","source":"The Hacker News","published":"2026-09-09T04:27:51.000Z","why":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch ","classes":[]},{"title":"CareCam Pro IP Cameras","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01","source":"CISA advisories","published":"2026-09-08T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-251-01.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to t","classes":[]},{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","url":"https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA advisories","published":"2026-09-08T12:00:00.000Z","why":"<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <ul> <li><a hre","classes":[]},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","url":"https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA advisories","published":"2026-09-04T12:00:00.000Z","why":"<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <ul> <li><a href=\"","classes":[]},{"title":"IXON VPN Client","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02","source":"CISA advisories","published":"2026-09-03T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-02.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to p","classes":[]},{"title":"Tycon Systems TPDIN-Monitor-WEB3","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08","source":"CISA advisories","published":"2026-09-03T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow for an attack","classes":[]},{"title":"Inductive Automation Ignition","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06","source":"CISA advisories","published":"2026-09-03T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow any authenticate","classes":[]},{"title":"Rockwell Automation ArmorStart LT","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04","source":"CISA advisories","published":"2026-09-03T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-04.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could result in a loss of","classes":[]},{"title":"Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07","source":"CISA advisories","published":"2026-09-03T12:00:00.000Z","why":"<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-169-07.json\"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Schneider Electric is aware of a vulnerability in the following products: ","classes":[]}]}